calhire
All posts
IntegrityAssessmentIntegrityAI in hiring

Fake candidates: proxy interviews, stolen identities and deepfakes

Remote hiring created a real identity-fraud problem: proxy interviewers, borrowed identities and deepfaked video. How the fraud works and where to verify.

CThe CalHire TeamCalHire8 min read

Reviewed by CalHire Compliance, Compliance & Fairness

Hiring fraud in remote processes takes three main forms: a proxy who sits the assessment or interview for someone else, an application submitted under a borrowed or stolen identity, and synthetic video used to pass a live call. The defence is to bind a verified identity to the assessment at the moment it happens, rather than trying to catch a fake later.

  • Three distinct frauds: proxy assessment, borrowed identity, synthetic video. They need different controls.
  • The FBI has publicly warned about deepfakes and stolen personal data used to apply for remote roles.
  • Identity has to be bound to the assessment at the moment of assessment, not checked at offer stage.
  • A portable verified profile is harder to fake than a fresh application, because it has a history.
  • Anti-fraud controls must not become a screen on accent, appearance or connection quality.

Three different frauds

"Fake candidates" gets used for three things that need three different controls. Conflating them is why most defences have a hole in them.

1. Proxy assessment. The applicant is real and wants the job; someone else does the technical work. Ranges from a friend helping with a take-home to commercial services that will sit a live interview while the candidate lip-syncs on camera. Most common, least sophisticated.

2. Borrowed or stolen identity. The person applying is not who the documents say. Sometimes a work-authorisation workaround, sometimes organised — the FBI's Internet Crime Complaint Center has publicly warned about stolen personal information and deepfakes being used to apply for remote positions, with particular concern about roles that touch customer or financial data.

3. Synthetic presence. Generated or manipulated video and audio used to pass a live call. The newest, the most discussed, and — for now — the rarest, because the first two are so much easier.

Notice the ordering: the effort curve runs opposite to the attention curve. Teams worry about deepfakes and get beaten by a friend on a screen share.

Why remote hiring opened this up

Nothing here is new in principle. What changed is that every verification point that used to be incidental disappeared at once.

An in-person process authenticated identity as a side effect: someone physically arrived, at a place, with a face, repeatedly, and did the technical work in a room. None of that was a control anyone designed — it was just how the process worked.

Remove the room and every one of those implicit checks vanishes simultaneously. Meanwhile the assessment became the only evidence, which raised the payoff for compromising it, and the market responded with services.

Where the defence belongs

The instinct is to add detection at the end: scrutinise the video call, check documents at offer stage, run a background check.

That is the wrong place, for a simple reason: by then the fraud has already produced its output. If a proxy sat the assessment, the score is fake, and everything downstream is reasoning from a fake number. Verifying identity at offer stage tells you who is signing the contract, not who did the work.

The control has to bind a verified identity to the assessment, at the moment of assessment. Everything else is cleanup.

What that looks like in practice

Verify the human at the start of the assessment. A document check plus a liveness check, establishing that a real, live person matching a real identity is present — once, at the moment that matters. This is a bounded check, not surveillance: it is different from watching someone for ninety minutes, and does not follow from it.

Make the assessment unique per session. A shared answer key is what makes proxy services efficient. Unique generation makes each fraud a bespoke effort.

Use session-level behavioural signals. Response latency patterns, typing cadence, paste behaviour, and cross-candidate answer similarity. A proxy sitting an assessment produces a different behavioural signature from a candidate composing.

Ask people about their own work. Still the single most effective control available. A ten-minute conversation asking someone to explain a decision in their own submission is very hard to pass on borrowed work, and it costs almost nothing.

Check consistency across the process. Does the assessment performance match the conversation? Sudden capability changes between stages are the clearest signal in the whole system.

Verify right-to-work properly, at the right stage. A real check on a real person once identity is revealed — not a document glance.

Watch for the operational tells in fully remote roles: mismatch between stated location and observed timezone behaviour, payment or equipment-address requests that don't fit the story, reluctance to appear on camera at any point, or the same phone number and bank details across several "different" candidates.

The trap: don't build a discrimination screen

This is where anti-fraud programmes go wrong, and the failure mode is predictable.

Verify identity. Do not assess authenticity.

"Does this government-issued document match this live face" is a bounded, auditable check with a clear answer. "Does this candidate seem legitimate to me" is an invitation to act on accent, name, appearance, lighting, background, connection quality and unfamiliar credentials — every one of which correlates with nationality, class and disability rather than with fraud.

The consequences of getting this wrong are worse than the fraud you are preventing: you reject honest candidates, concentrated in specific groups, on the basis of an accusation you cannot substantiate. That is an adverse-impact problem and a reputational one at the same time.

So:

  • Never auto-reject on a fraud signal. Route to a trained human reviewer.
  • Give the candidate a route to respond. Most flags resolve either way in one short conversation.
  • Log the decision and the reason, tied to the reviewer.
  • Measure flag rates by group. If they diverge, your control is measuring something other than fraud.
  • Separate the fraud question from the hiring question. A resolved flag should not linger as a suspicion.

How CalHire's model makes this harder to attack

CalHire's structure changes the economics of assessment fraud rather than adding a detector on top:

  • Identity assurance with liveness checks at the point of assessment, so a verified real human is bound to the score at the moment the score is created.
  • CalHire is the identity broker. We verify the real human and hold that identity, revealing it only on mutual progress with the candidate's consent — per employer, recorded in an immutable ledger. Employers receive a verified person at reveal, rather than a claim they have to check themselves.
  • One portable verified profile, valid 90 days with a freshness badge and a 30-day retake cooldown. A profile with history is materially harder to fabricate than a fresh application, and the cooldown removes the retake-until-lucky strategy.
  • Unique-per-session assessment generation — no shared answer key.
  • Behavioural and originality signals producing a risk score that routes to a human, never an auto-fail.
  • Text-only AI interview; video is human-only and post-reveal, so a synthetic-video attack has nothing to attack during evaluation.
  • Right-to-work details unlock with identity at reveal, for that one employer.

The integrity layer and the reveal mechanics are on the features page; the identity-broker model is described on for employers.

The structural insight is worth keeping: fraud targets the moment where value is created. In hiring that moment is the assessment, not the offer. Put your verification there and most of the problem stops being economic for the attacker.

Frequently asked questions

How common is candidate identity fraud?
Common enough that law enforcement has issued public warnings. The FBI’s Internet Crime Complaint Center published an advisory on deepfakes and stolen personally identifiable information being used to apply for remote work positions, particularly roles with access to customer or financial data. Volume varies enormously by role, seniority and whether the position is fully remote.
What is a proxy interview?
Someone other than the applicant sits the technical assessment or interview. It ranges from informal help during a take-home to paid services that will sit a live interview on a candidate’s behalf while the candidate appears on camera. It is the most common form of assessment fraud and the least technically sophisticated.
How do you detect a deepfake in a live interview?
Detection from video alone is unreliable and getting harder, so it is a poor place to put your defence. The stronger control is binding identity earlier — verifying the real person at the point of assessment, with liveness checks — so that by the time you are on a call, you are talking to someone whose identity was already established rather than trying to authenticate them visually in real time.
How do you stop fraud controls from becoming discriminatory?
By verifying identity rather than judging authenticity. "Does this government ID match this live face" is a bounded check. "Does this person seem legitimate" invites judgements about accent, appearance, name, connection quality and background — which is a discrimination problem, not a fraud control. Route every risk signal to a trained human reviewer with an appeal route, and never auto-reject.
Share this post

Keep reading

Integrity8 min

Candidates are using AI in your assessments. Now what?

AI-text detectors are unreliable and disproportionately flag non-native speakers. What to do instead: assessment design, behavioural signals, and human review.

Integrity8 min

Why webcam proctoring is the wrong fix for assessment integrity

Webcam proctoring flags disabled candidates, people with darker skin and anyone without a private room. What it costs, and what to measure instead.

Hiring decided by proven skills

Create a free verified profile, or see how anonymous-first hiring works for your team.